Export limit exceeded: 15883 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15883 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66461 | 2 Smepay, Wordpress | 2 Smepay:upi Gateway For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66467 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcommunity | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66653 | 2 Edge-themes, Wordpress | 2 Barista, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66656 | 2 Mikado-themes, Wordpress | 2 Foton Core, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66657 | 2 Mikado-themes, Wordpress | 2 Biagiotti, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66658 | 2 Mvp Themes, Wordpress | 2 Reviewer, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66704 | 2 Jegstudio, Wordpress | 2 Gutenverse, Wordpress | 2026-08-14 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||
| CVE-2026-73188 | 2 Iqonic, Wordpress | 2 Kivicare, Wordpress | 2026-08-14 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. | ||||
| CVE-2026-73340 | 2 Fifu, Wordpress | 2 Featured Image From Url, Wordpress | 2026-08-14 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | ||||
| CVE-2026-73346 | 2 Mailchimp, Wordpress | 2 Mailchimp For Woocommerce, Wordpress | 2026-08-14 | 7.6 High |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | ||||
| CVE-2026-73353 | 2 Revolut, Wordpress | 2 Revolut Gateway For Woocommerce, Wordpress | 2026-08-14 | 5.3 Medium |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | ||||
| CVE-2026-57804 | 2 Codexthemes, Wordpress | 2 Thegem Theme Elements (for Elementor), Wordpress | 2026-08-14 | 7.5 High |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | ||||
| CVE-2026-19794 | 2 Gamerz, Wordpress | 2 Wp-stats, Wordpress | 2026-08-14 | 7.2 High |
| The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-18109 | 2 Boldgrid, Wordpress | 2 W3 Total Cache, Wordpress | 2026-08-14 | 7.2 High |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. | ||||
| CVE-2026-65480 | 2 Codexthemes, Wordpress | 2 Thegem, Wordpress | 2026-08-14 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. | ||||
| CVE-2026-73532 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms | 2026-08-14 | 9.8 Critical |
| Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal. | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28155 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28157 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.5 High |
| Subscriber Path Traversal in Do Lasso <= 358 versions. | ||||